The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

The relevance scoring algorithm

Prev Next

Common Platform Enumeration to identify vulnerable systems

If the operating system does not completely match, the result of the attack is inconclusive. In such circumstances, the Manager assigns a partial relevance score by way of a scoring algorithm. Scoring relies on the matching each component of the Common Platform Enumeration (CPE) name of attack signature with CPE name of the target system. CPE™ is a standardized method of describing and identifying classes of applications, operating systems, and hardware devices present among an enterprise's computing assets. CPE can be used as a source of information for enforcing and verifying IT management policies relating to these assets, such as the vulnerability of a target system to a malicious attack. Trellix IPS collects information about servers, workstations and other devices on the network, identifies these products using their CPE names, and uses this standardized information when matching the CPE of the attack signature to the CPE of each device. For more information on CPE, you can go to http://cpe.mitre.org.

CPEs are represented in a certain order and with a specific syntax. The universal CPE format is represented in the following figure.

CPE Format
CPE Format


How CPE influences the relevance score

Each component in the CPE is given a specific weight depending on the potential of that component to contribute to the vulnerability of the system. The table below presents the various components in the CPE that are used to compute the relevance score:

Components of a CPE and their weights

Component

What it signifies

Carries a weight of

Part

First component in the CPE, which is a single letter code that designates the particular platform part that is being identified. The following codes are defined for the part:

  • h – hardware part

  • o – operating system part

  • a – application part

0

Vendor

Second component in the CPE name, which refers supplier or vendor of the platform part. Example: Microsoft, Redhat, etc.

10

Product

Third component in the CPE name, which refers a specific product developed by the vendor. Example: Windows XP, Windows NT, Enterprise Linux, etc.

30

Version

Fourth component in the CPE name, which refers to a specific version of the product. Example: 4.0 for Window NT, 4 for Enterprise Linux, etc.

20

Update

Fifth component in the CPE name, which refers to a specific update of the version. Example: SP6 for Wndows NT, Update 4 for Enterprise Linux, etc.

20

Edition

Sixth component in the CPE name, which refers to the edition of the product. Example: Workstation, Server, etc.

15

Language

Seventh component of the CPE name, which refers to the language of the product. Example: English, Spanish, etc.

5



The illustrative diagram below shows the format and correlates it with real world products and in turn with weights as displayed in the table above.

CPE Illustration
CPE Illustration


Following are a few examples of CPEs:

  • cpe:/o:microsoft:windows_xp:::pro

  • cpe:/a:adobe:reader:8.1

  • cpe:/o:redhat:enterprise_linux:4:update4

CPE name matching logic

To compute the relevance score, the CPE of the attack signature is matched with every component of the CPE of the target system. If any component is not mentioned in the attack signature CPE, it applies to all instances that can occupy that position. For example cpe:/o:microsoft:windows_xp applies to all versions, updates, editions, and languages of Microsoft Windows XP.

A CPE match is considered definitive.

A few more examples to illustrate the name matching logic are presented below:

  • Case 1 – cpe:/o:microsoft:windows:xp will match all the operating system variants mentioned below:

    • cpe:/o:microsoft:windows:xp::sp1

    • cpe:/o:microsoft:windows:xp::sp2

    • cpe:/o:microsoft:windows:xp

    • cpe:/o:microsoft:windows:xp::sp1:professional

    • cpe:/o:microsoft:windows:xp::sp1::en

  • Case 2 – cpe:/o:microsoft:windows:xp::sp1 will not match cpe:/o:microsoft:windows:xp::sp2 because not all parameters of the attack signature CPE match the target system CPE.

Scenarios to understand score computation

Refer to the table below to view some scenarios for alert relevance scoring.

Illustrating relevance score calculation through examples

Attack signature CPE

Description of the attack signature CPE

Target system CPE

How the two CPEs match up

Relevance score

cpe:/o:microsoft:windows_xp::sp2

This attack is relevant to all Microsoft Windows XP SP2 systems, irrespective of which version, edition, and language they use.

cpe:/o:microsoft:windows_xp::sp2:professional

Since the CPE from the attack signature is considered definitive, and all components of the target system CPE match the components of the attack signature CPE, the alert generated is 100% relevant.

100%

cpe:/o:microsoft:windows_xp

Since the CPE from the attack signature is considered definitive, and only the {part}, {vendor}, and {product} components of the attack signature CPE, and not the {update} component, matches the target system CPE, the alert generated has a relevance of 100 - 20 = 80%.

80%

cpe:/o:microsoft:windows_xp::sp3

Since the CPE from the attack signature is considered definitive, and the {part}, {vendor}, and {product} components of the attack signature CPE match that of the target system CPE, the alert might initially appear relevant. However, notice that the {update} component of the target system CPE is present but different than that of the attack signature CPE. This means that the alert generated will not be relevant and the score will be 0%.

0%



Special scenarios in which the relevance score is computed

  • In day-to-day operations, not every attack that is mounted and consequently every attack signature CPE that is extracted is as straightforward as those that are mentioned above. In some cases of device profiling, a thorough analysis might not be possible. As a result, device profiling does not isolate the operating system and presents a possibility of more than one operating system. The relevance score is calculated by as the average relevance score of all the matched CPEs.

    Presented in the table below are some such scenarios where the relevance score is computed for a group of CPEs.

    Representation of a group CPE
    Representation of a group CPE


    Illustrating relevance score calculation for group CPEs through examples

    Host group CPE

    Maps to individual CPEs

    CPE match scenarios

    Relevance score logic

    Relevance score

    cpe:/o:microsoft:windows_2000_windows_xp_windows_2003

    cpe:/o:microsoft:windows_xp

    cpe:/o:microsoft:windows_2000

    cpe:/o:microsoft:windows_server_2003

    Case 1: All CPEs match

    cpe:/o:microsoft:windows_xp

    cpe:/o:microsoft:windows_2000

    cpe:/o:microsoft:windows_server_2003

    Since all the CPEs match, the relevance score is computed as the maximum.

    100%

    Case 2: Two CPEs match

    cpe:/o:microsoft:windows_xp

    cpe:/o:microsoft:windows_server_2000

    Since only two of three CPEs match, the score will be computed as 200/3 = 66%.

    66%

    Case 3: One CPE matches

    cpe:/o:microsoft:windows_xp

    cpe:/o:microsoft:windows_server_2008

    Since only one of three CPEs matches, the score will be computed as 100/3 = 33%.

    33%

    Case 4: Two CPEs match

    cpe:/o:microsoft:windows_xp

    cpe:/o:microsoft:windows_server_2000

    cpe:/o:microsoft:windows_server_2008

    Since only two of three CPEs match, the score will be computed as 200/3 = 66%.

    66%



  • There are also cases when conventional methods of calculating a relevance score are not able to provide a score. This is especially noticed when the exact details of the operating system are not available. It can also be noticed when the attack is being launched through an application and details of the application are not available. In such instances, the Manager relies on the attack signature to be able to provide you more clarity.

    The Manager determines the vulnerable application and uses the signature to decipher the operating system it is compatible with. It then compares this operating system to the target operating system. If they match, a default score of 50% is displayed. If they do not match, a score of 0% is displayed. For example, if the application is one that runs only on a Linux-based operating system but the attack is directed at a system running Microsoft Windows, the attack will not be relevant. Or, assume that the attack is one that exploits a vulnerability in Microsoft Word (which is assumed to only be compatible with Microsoft Windows) and the target environment is running some Microsoft product, a default score of 50% will be displayed, prompting you to further investigate.